PT-2026-96735 · Misp · Misp
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
The
RequestHandlerComponent automatically decodes XML request bodies on all write requests. A logic error exists in the Xml::build() library within its readFile guard condition due to PHP operator precedence, which allows the HTTPS branch to bypass the readFile check. Consequently, a request body containing a bare HTTPS URL is treated as a locator and fetched by the server. Since the /cspReport endpoint accepts XML content types and is unauthenticated, a remote attacker can send a POST request with a crafted XML body to force the server to issue outbound HTTPS requests to arbitrary targets. This can be used to probe internal services, trigger actions on internal HTTPS endpoints, or perform timing-based reconnaissance of the network environment.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Misp